Skip to content

test(sdk): gate the public API snapshot on secret-bearing exports - #471

Open
Hustler490 wants to merge 1 commit into
Sub-Rosa-Issue:mainfrom
Hustler490:fix/412-public-api-snapshot-secret-gate
Open

Hustler490 wants to merge 1 commit into
Sub-Rosa-Issue:mainfrom
Hustler490:fix/412-public-api-snapshot-secret-gate

Conversation

@Hustler490

Copy link
Copy Markdown

Closes #412

What

The public-API snapshot test could not be the gate the issue asks for: it compared a hardcoded name list only, and it could not even run because the SDK barrel was broken.

Changes

  • packages/sdk/src/errors.ts - restores the missing ROUND_CONTRACT_ERRORS block (RoundContractErrorCode, RoundContractErrorSpec, ContractErrorEntry, the frozen code map, ROUND_CONTRACT_ERRORS_BY_NAME, getRoundContractError, isRoundContractErrorRetryable, diffContractErrorMapping). index.ts re-exports these, so without them importing the SDK threw. Also includes EscrowNotConserved (feat(tlock): add auditor identity recovery cli (#29) #40) from types.rs.
  • packages/sdk/src/public-api.snapshot.json - the committed surface: the true 107 runtime exports plus a committed secretMentionAllowlist (currently ["SubRosaClientConfig"], the documented credential surface that carries secretKey).
  • packages/sdk/src/public-api-snapshot.test.ts - rewritten to:
    • fail on any extra or missing export vs. the committed snapshot;
    • fail on any export whose name or declaration signature mentions a secret, seed, private/raw/signing keypair, or mnemonic, unless it is on the allowlist (snapshot membership does not exempt - only the allowlist does);
    • assert the allowlist has no dangling entries;
    • include focused guard tests (secret name, secret-typed parameter, raw keypair type, snapshot-listed-but-not-allowlisted, allowlisted case);
    • read source declarations only - it does not start a network client.

Acceptance criteria

  • Current public surface matches the snapshot (107 exports).
  • An extra export fails the test (extra/missing diff).
  • A secret-accepting export fails even if snapshot-listed, unless allowlisted.
  • The test does not start a network client.

Validation

  • node --import tsx --test src/public-api-snapshot.test.ts ? 11/11 pass.

Note on the repo state

main also has pre-existing, unrelated breakage that this PR does not introduce and does not attempt to fix: errors.test.ts cannot pass because contracts/round/ERRORS.md maps code #40 to SealRoundTooEarly while types.rs maps #40 to EscrowNotConserved (mutually exclusive), and pnpm typecheck already reports errors in conservation.ts, network.test.ts, seal-fixture.ts, and tlock/src/seal.ts. The restored block is a strict improvement over the previously un-importable barrel.

@Hustler490
Hustler490 force-pushed the fix/412-public-api-snapshot-secret-gate branch from fbe8a77 to d37f923 Compare October 4, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fail the SDK export snapshot when a secret-bearing symbol is public

2 participants